Best way to filter "Nachi pings"?

From: Brett Glass (brett_at_lariat.org)
Date: 10/27/03

  • Next message: Kris Kennaway: "Re: Best way to filter "Nachi pings"?"
    Date: Mon, 27 Oct 2003 00:31:46 -0700 (MST)
    To: security@freebsd.org
    
    

    We're being ping-flooded by the Nachi worm, which probes subnets for
    systems to attack by sending 92-byte ping packets. Unfortunately,
    IPFW doesn't seem to have the ability to filter packets by length.
    Assuming that I stick with IPFW, what's the best way to stem the
    tide?

    --Brett Glass
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Kris Kennaway: "Re: Best way to filter "Nachi pings"?"

    Relevant Pages

    • Re: Best way to filter "Nachi pings"?
      ... > We're being ping-flooded by the Nachi worm, which probes subnets for ... > systems to attack by sending 92-byte ping packets. ... > IPFW doesn't seem to have the ability to filter packets by length. ...
      (FreeBSD-Security)
    • Re: ICMP Killed me and my machine
      ... Niether your limiting or IPFW will fix the problem with your bandwidth being ... eaten by the attack. ... >> Network Admin., DataSyrge Internet Svces. ...
      (FreeBSD-Security)
    • Re: machine hangs on occasion - correlated with ssh break-in attempts
      ... A machine I manage remotely for a friend comes under a distributed ssh ... break-in attack every once in a while. ... distributed brute-force attack (e.g. 300,000 different IPs) was launched ... willing to bet adding 300,000 individual ipfw entries would cause some ...
      (FreeBSD-Security)
    • Re: machine hangs on occasion - correlated with ssh break-in attempts
      ... A machine I manage remotely for a friend comes under a distributed ssh ... break-in attack every once in a while. ... distributed brute-force attack (e.g. 300,000 different IPs) was launched ... willing to bet adding 300,000 individual ipfw entries would cause some ...
      (freebsd-stable)
    • Re: machine hangs on occasion - correlated with ssh break-in attempts
      ... I haven't explored this issue enough to speak with any authority - but once upon a time I had an app doing tons of ipfw rule add/removes all the time and we had no end of performance and stability problems on that box. ... A machine I manage remotely for a friend comes under a distributed ssh break-in attack every once in a while. ... Aug 12 10:21:17 symbion sshd: Invalid user mythtv from 85.234.158.180 ...
      (freebsd-stable)